Specialist assessment · Exchange Online

Find the messaging controls and access paths that matter beyond the mailbox.

A focused Exchange Online security assessment covering mail flow, administrative and application access, protection settings, public email authentication, auditing, and operational ownership.

Technical scope

Review how messages, permissions, applications, and exceptions move through the service.

Coverage is adjusted for Exchange Online licensing, hybrid dependencies, accepted mail-flow design, third-party gateways, Microsoft Defender for Office 365 licensing, and the domains included in scope.

Mail flow and connectors

Review inbound and outbound connectors, transport rules, accepted domains, relay assumptions, third-party gateway dependencies, and ownership of exceptional routing.

Forwarding and mailbox access

Assess external forwarding controls, inbox-rule risk signals where available, shared and resource mailbox governance, delegates, Full Access, Send As, and Send on Behalf assignments.

Administration and applications

Review Exchange administrative roles, role groups, service principals, application access controls where used, automation dependencies, and privileged operational paths.

Built-in protection

Evaluate anti-spam, anti-malware, connection filtering, spoof handling, quarantine dependencies, and standard protection settings that apply to the licensed service.

Email authentication

Review SPF, DKIM, DMARC, Microsoft 365 DKIM selector records, alignment, reporting ownership, and the limits of conclusions drawn from public DNS.

Audit and operations

Assess mailbox and administrative audit availability, alert and investigation paths, retention dependencies, change records, exception reviews, and ownership of messaging incidents.

Questions this assessment can answer

Turn messaging complexity into reviewable decisions.

Where can mail leave unexpectedly?

Review forwarding, connectors, transport rules, delegates, applications, and exceptional routing against documented business need.

Who can act through a mailbox?

Identify administrative, delegated, shared-mailbox, and application access paths that need clearer scope, ownership, or periodic review.

Can an investigation reconstruct change?

Evaluate audit availability, alerting, retention dependencies, ownership, and the evidence path for suspicious forwarding, access, or mail-flow changes.

Assessment process

A controlled review from scope to decision.

01 · MAP

Map messaging architecture

Confirm domains, mail gateways, hybrid elements, connectors, applications, privileged teams, regulated workflows, licensing, and known exceptions.

02 · REVIEW

Review configuration and access

Collect agreed evidence for mail flow, forwarding, delegates, administration, applications, protection, email authentication, and audit controls.

03 · TRACE

Trace material paths

Follow representative inbound, outbound, delegated, automated, and exceptional flows to resolve ownership, necessity, and control coverage.

04 · PRIORITIZE

Build the action register

Prioritize changes by exposure, business dependency, affected domains or mailboxes, investigation value, and operational change risk.

Deliverables

A messaging-security plan grounded in configuration and ownership.

  • Executive summary of material Exchange Online risk and business dependency
  • Mail-flow, connector, forwarding, mailbox-access, and application findings
  • Email-authentication and domain-control observations
  • Audit, alerting, exception, and operational ownership review
  • Prioritized action register with dependencies and validation steps
Boundaries

Clear scope protects the quality of the answer.

  • No ordinary mailbox-content review in the standard engagement
  • Advanced Defender capabilities only where licensed and included in scope
  • Public DNS observations do not prove internal Microsoft 365 configuration
  • No mail-flow, forwarding, connector, delegate, or protection changes during assessment
  • On-premises Exchange and network infrastructure require an explicitly expanded scope
Frequently asked questions

Questions to resolve before the work begins.

Does the Exchange Online assessment read employee email?

The standard assessment focuses on configuration, permissions, mail flow, protection settings, audit evidence, and operational records. It does not read ordinary mailbox content. Any exceptional content need would require explicit justification and authorization.

Is Microsoft Defender for Office 365 included?

Exchange Online built-in protections and dependencies are reviewed as applicable. Advanced Microsoft Defender for Office 365 capabilities receive detailed treatment only where licensed and included; a dedicated Defender assessment is available.

Does the review include SPF, DKIM, and DMARC?

Public email-authentication and mail-routing records can be reviewed alongside relevant Exchange Online configuration. Public DNS alone cannot establish the state of internal tenant controls.

Can hybrid Exchange be included?

Cloud-side connectors, mail flow, identities, and dependencies can be included by agreement. A deep review of on-premises Exchange servers, operating systems, and network infrastructure requires an explicitly expanded scope.

Related services and evidence

Defender for Office 365 Assessment

Go deeper on Safe Links, Safe Attachments, anti-phishing, submissions, investigation, response, and campaign visibility where licensed.

Review Defender for Office 365 →

Exchange Online assessment checklist

Prepare an evidence-led review of mail flow, forwarding, SMTP AUTH, connectors, auditing, and email authentication.

Use the Exchange checklist →

External Exposure Scan

Check directional public SPF, DMARC, Microsoft 365 DKIM selector, DNSSEC, and mail-routing signals without tenant access.

Run the external scan →

Microsoft 365 Security Audit

Expand the review across identity, access, collaboration, endpoint, applications, and security operations.

Review the tenant-wide audit →

Start with the decision your team needs to make.

Share the business trigger, relevant Microsoft 365 licensing, approximate environment size, and decision deadline. No credentials or tenant exports are needed for the first conversation.